Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 743865 (CVE-2020-36427) - <media-gfx/gthumb-3.10.2: DoS via malformed JPEG (CVE-2020-36427)
Summary: <media-gfx/gthumb-3.10.2: DoS via malformed JPEG (CVE-2020-36427)
Status: RESOLVED FIXED
Alias: CVE-2020-36427
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://download.gnome.org/sources/gt...
Whiteboard: B3 [noglsa cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2020-09-21 00:50 UTC by John Helmert III
Modified: 2022-08-10 23:57 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2020-09-21 00:50:46 UTC
According to 3.10.1 changelog at $URL:

 Bugs fixed:

  * WebP loader: fixed an infinite loop when the operation is cancelled. (Jürg Billeter)
  * Jpeg loader: fixed crash in case of some malformed jpegs. (Joerg Fellmann)
  * Fixed crash when selecting other images after deleting. (#126)


Please bump to 3.10.1.
Comment 1 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-02-21 04:05:06 UTC
x86 done
Comment 2 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-02-21 04:30:33 UTC
amd64 done

all arches done
Comment 3 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2021-02-21 04:34:03 UTC
Please cleanup, thanks!
Comment 4 Larry the Git Cow gentoo-dev 2021-02-28 13:08:17 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=dce71c653b6213576fc0ac27963b8d052c8d0d47

commit dce71c653b6213576fc0ac27963b8d052c8d0d47
Author:     Mart Raudsepp <leio@gentoo.org>
AuthorDate: 2021-02-28 13:08:12 +0000
Commit:     Mart Raudsepp <leio@gentoo.org>
CommitDate: 2021-02-28 13:08:12 +0000

    media-gfx/gthumb: security cleanup
    
    Bug: https://bugs.gentoo.org/743865
    Package-Manager: Portage-3.0.12, Repoman-3.0.2
    Signed-off-by: Mart Raudsepp <leio@gentoo.org>

 media-gfx/gthumb/Manifest             |  1 -
 media-gfx/gthumb/gthumb-3.10.0.ebuild | 89 -----------------------------------
 2 files changed, 90 deletions(-)
Comment 5 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2021-07-19 01:41:13 UTC
>   * Jpeg loader: fixed crash in case of some malformed jpegs. (Joerg
> Fellmann)

Requested a CVE for this, seems like the only one that's really security relevant. The others would require the user to do it to themselves.
Comment 6 NATTkA bot gentoo-dev 2021-07-29 17:25:53 UTC
Package list is empty or all packages have requested keywords.
Comment 7 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-08-10 23:57:21 UTC
(In reply to John Helmert III from comment #5)
> >   * Jpeg loader: fixed crash in case of some malformed jpegs. (Joerg
> > Fellmann)
> 
> Requested a CVE for this, seems like the only one that's really security
> relevant. The others would require the user to do it to themselves.

And since this is so low impact, no GLSA. All done!